Launch Week Day 1: Announcing Security Design Review
MEDIUM 4.3 Maven

Obfuscated email addresses should not be sorted

GHSA-g9w4-prf3-m25g · CVE-2023-38509

Published · Modified

Description

Impact

The mail obfuscation configuration was not fully taken into account and is was still possible by obfuscated emails.

See https://jira.xwiki.org/browse/XWIKI-20601 for the reproduction steps.

Patches

This has been patched in XWiki 14.10.9, and XWiki 15.3-rc-1.

Workarounds

The workaround is to modify the page XWiki.LiveTableResultsMacros following this patch.

References

For more information

If you have any questions or comments about this advisory:

Ready to move

Start Securing

Free, no credit card | First findings in minutes